CVE detail
CVE-2026-8088
A weakness has been identified in OSGeo gdal up to 3.13.0dev-4. The affected element is the function GDfieldinfo of the file frmts/hdf4/hdf-eos/GDapi.c. Executing a manipulation can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Upgrading to version 3.13.0RC1 is sufficient to fix this issue. This patch is called a791f70f8eaec540974ec989ca6fb00266b7646c. The affected component should be upgraded.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 9.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- https://vuldb.com/vuln/361841/ctivuldb.com
No excerpt available.
Exploitvuldb.comMay 7, 2026, 8:16 PM - https://vuldb.com/vuln/361841vuldb.com
No excerpt available.
Exploitvuldb.comMay 7, 2026, 8:16 PM - https://vuldb.com/submit/808040vuldb.com
No excerpt available.
Exploitvuldb.comMay 7, 2026, 8:16 PM No excerpt available.
Exploitgithub.comMay 7, 2026, 8:16 PMNo excerpt available.
Exploitgithub.comMay 7, 2026, 8:16 PMNo excerpt available.
Exploitgithub.comMay 7, 2026, 8:16 PMNo excerpt available.
Exploitgithub.comMay 7, 2026, 8:16 PM- https://github.com/OSGeo/gdal/github.com
No excerpt available.
Exploitgithub.comMay 7, 2026, 8:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
2 repository references · best confidence 0.90 · max 0 stars
- biniamf/pocsHigh confidencegithubNVD Exploit reference0 starsDiscovered Jul 20, 2026, 6:20 PM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
- OSGeo/gdalHigh confidencegithubNVD Exploit reference0 starsDiscovered Jul 20, 2026, 6:20 PM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-8213CVSS 1.9 · Low
A vulnerability has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this issue is the function GDSDfldsrch of the file frmts/hdf4/hdf-eos/GDapi.c of the component Grid Fil…
- CVE-2026-8212CVSS 1.9 · Low
A flaw has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this vulnerability is the function SWSDfldsrch of the file frmts/hdf4/hdf-eos/SWapi.c. Executing a manipulation…
- CVE-2026-8084CVSS 1.9 · Low
A vulnerability was determined in OSGeo gdal up to 3.13.0dev-4. This vulnerability affects the function memmove of the file frmts/hdf4/hdf-eos/SWapi.c of the component HDF-EOS Gri…
- CVE-2026-18790CVSS 1.9 · Low
A weakness has been identified in Systerel S2OPC up to 1.7.3. This affects the function LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse of the file src/ClientServer/frontend/…
- CVE-2026-18583CVSS 5.5 · Medium
A weakness has been identified in mz-automation libiec61850 up to 1.6.1. This issue affects the function checkDataSetAccess of the file src/iec61850/server/mms_mapping/mms_mapping…
- CVE-2026-43767CVSS 5.0 · Medium
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected s…